MOMR: A Threat in Web Application Due to the Malicious Orchestration of Microservice Requests

Chunyang Zheng, Jinfa Wang, Shuaizong Si, Zhi Li, Nan Yu, Limin Sun · 2024

Microservice is an increasingly favored architecture for constructing modern web applications and the fast-paced business requirements facilitate the transmission of microservice traffic among distributed servers. In contrast to traditional architectures, microservice architecture has tight inherent dependencies between microservice units when supporting web application business. Attackers can excavate these dependencies to maliciously orchestrate microservice requests, scheduling microservice traffic to converge on the target link. This attack disrupts link and application quality of service, bringing new potential threats to web applications and cyberspace security. This work analyzes and evaluates the threat due to the malicious orchestration of microservice requests (MOMR) with the initial intention of promoting microservice application security and other information system security based on the microservice architecture. A Cross-Layer Coupling (CLC) model is proposed that aims to describe microservice traffic transmission, which efficiently supports the threat evaluation. A Path-aware Microservice Traffic Scheduling (PMTS) attack method is imposed on the CLC model so that it can construct the MOMR threat accurately. To demonstrate the effectiveness of the proposed method in evaluating the MOMR threat, a comprehensive analysis is performed on a typical microservice application and a semi- physical simulation platform. The result shows the threat causes performance degradation and impacts the network, such as a packet loss rate of up to 79% and an RTT increase of 600% of the target link.

Read the paper · More papers on PaperTik